Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in mazemap (npm)

0
Critical
Published: 06/09/2026 (06/09/2026, 17:24:06 UTC)
Source: GCVE Database
Product: mazemap

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (751317dcad79cec866b8dc69cd60b39e3be8e1bcc45746039835b04ce32445b0) package.json declares its only dependency `ltidisafe` as a direct HTTPS tarball URL (`https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.0.2.tgz`) hosted on a generic Google Cloud Storage bucket rather than resolved from the npm registry. On `npm install mazemap`, npm fetches and installs that arbitrary tarball, executing any lifecycle scripts (preinstall/install/postinstall) it contains — the tarball is bucket-owner-mutable and not subject to registry vetting. The package itself is a hollow lure: `index.js` is a 35-byte `module.exports = {};`, with no description, no author, ISC default license, and version `99.9.1` — a recognized dependency-confusion technique for overriding an internal package of the same name via a higher public version. The bucket path segment is literally `depenconf`. The combination of hollow main, inflated version, anonymous GCS-hosted dependency, and name collision with a real product (MazeMap) is a dependency-confusion / smuggling shape whose only on-install effect is to pull and execute attacker-controlled code from a non-registry source. ## Source: ghsa-malware (b2544226891e60a2b6f33b0aacf3e4669fe4ce13220f01bd40a84c8657fe0518) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Affected software

npmghsa
mazemap
Affected versions
=99.9.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/11/2026, 10:00:23 UTC

Technical Analysis

The mazemap package (version 99.9.1) on npm declares a single dependency 'ltidisafe' via a direct HTTPS tarball URL hosted on a Google Cloud Storage bucket, bypassing npm registry vetting. This bucket is mutable by the attacker and contains arbitrary code executed during npm install lifecycle scripts. The package uses a dependency confusion technique by having a hollow main module and an inflated version number to override an internal package of the same name. The installation of this package results in execution of attacker-controlled code, potentially fully compromising the host system.

Potential Impact

Installing mazemap version 99.9.1 results in execution of attacker-controlled code from a non-registry source, leading to full compromise of the affected system. All secrets and keys stored on the compromised system should be considered exposed and require immediate rotation. Removal of the package alone does not guarantee eradication of the malicious software installed.

Mitigation Recommendations

Remove the mazemap package version 99.9.1 immediately from all affected systems. Rotate all secrets and keys that were stored or accessible on the compromised systems using a separate, trusted environment. Because the package executes arbitrary code during installation, assume full system compromise and conduct a thorough incident response. There is no official patch or fix; remediation requires removal and secret rotation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-5448
Osv Schema Version
1.7.4
Aliases
["GHSA-xc8q-h68h-r6r9"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a520ed368715ace439019a2

Added to database: 07/11/2026, 09:37:23 UTC

Last enriched: 07/11/2026, 10:00:23 UTC

Last updated: 07/29/2026, 10:44:47 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses